QUANTASEAL
QUANTASEAL
All three deployment models run the identical QuantaSeal platform. Private Cloud and Air-Gapped add data sovereignty and key custody guarantees that SaaS cannot provide.
Managed by QuantaSeal
From $69 AUD/mo
Your VPC, your keys
Custom pricing
Fully offline, fully sovereign
Custom pricing
For organisations that cannot send cryptographic material or sensitive data to a third-party cloud — Private Cloud delivers the full QuantaSeal platform within your own boundary.
All encryption keys stay within your KMS. QuantaSeal staff can never access your tenant keys or decrypt your data. Per-tenant CMK hierarchy with zero shared secrets.
All data processing, key operations, and audit logs remain within your infrastructure boundary. Meets APRA CPS 234 data residency requirements without waivers.
Same ML-KEM-768 + ML-DSA-65 + AES-256-GCM hybrid encryption as the SaaS product. NIST FIPS 203/204/205 compliant. No feature compromise for on-premises.
Deploy with a single Helm chart or docker-compose.yml. Supports EKS, AKS, GKE, k3s, bare-metal, and any OCI-compliant runtime. Upgrade with helm upgrade.
Run entirely on private IP space. No outbound internet required for key operations. Integrates with your internal certificate authority and private DNS.
Optionally backed by HSM (Thales nShield, AWS CloudHSM, Azure Dedicated HSM). Private Cloud includes HSM connector configuration for maximum key security.
Private Cloud was designed specifically for organisations facing strict regulatory requirements around data residency, key custody, and cryptographic sovereignty.
Australian Prudential Regulation Authority requires regulated entities to maintain control of their cryptographic material. Private Cloud deployment satisfies the data residency and key custody obligations without needing a regulatory waiver.
EU customers can deploy QuantaSeal Private Cloud in eu-west-1 or eu-central-1. All PII processing, key operations, and audit logs stay within the EU — satisfying Article 46 without Standard Contractual Clauses.
Air-gapped deployment supports PROTECTED and SECRET data classifications. Offline licence validation, air-gap installation bundle, and isolated update channel available for government and defence customers.
Private Cloud deploys like any enterprise Kubernetes application. Full Helm chart, Docker Compose, and bare-metal options included.
Contact sales for Private Cloud pricing. You'll receive a licence key and Docker Hub pull credentials.
Spin up your VPC or Kubernetes cluster. Our infrastructure checklist ensures you meet minimum requirements.
One helm install command deploys the full QuantaSeal stack — API, database, Redis, and Prometheus metrics.
Point your DNS to the private load balancer. Same admin console, same API, same compliance features — all within your perimeter.
QuantaSeal Private Cloud runs on any OCI-compliant container runtime. Tested and validated on all major Kubernetes distributions.
Helm Install
Single command deployment
Contact our enterprise team for Private Cloud licensing, infrastructure sizing, and APRA compliance documentation. Most deployments go live within 2 business days.